I'm a versatile security specialist with a breadth of experience. A decade of penetration testing and security consultancy, combined with considerable engineering experience, allow me to quickly identify, understand and solve security requirements for organisations big and small. I especially enjoy designing and building right-sized solutions to common security concerns for growing organisations, and I love to get my hands dirty in the technical details.
-
Senior Security EngineerFly.Io Jan 2023 - Sep 2024Auckland, New ZealandI joined Fly.io in the early days of the security practice, and led a number of initiatives to implement core capabilities across areas of corporate, infrastructure, product and application security. Some of these include:-- Implementation of a SIEM, including developing integrations with services, as well as detection engineering and designing alert triage strategies.-- Implementation of an osquery-based endpoint monitoring system, with a focus on posture management, vulnerability management and detecting indicators of compromise.-- Application and product security, code and architecture review, CI/CD security, application and network penetration testing.-- Implementation of eBPF-powered security observability on infrastructure hosts, including those responsible for hosting untrusted workloads. This focused on providing low-level visibility to our infrastructure to identify common TTPs used for initial access and lateral movement.-- Undertook in-depth research around the security of GPU virtualisation, specifically to gain visibility of malicious activity at the hypervisor level.-- Engineering of custom integration between endpoint management, SIEM, and users, to allow users to take responsibility for security events that may affect them, with full oversight from the security team.This was alongside the work general security staffing in a relatively small organisation, which included authoring security-related documentation and policy, education, threat hunting and intelligence and responding to incidents. -
Principal Security Consultant (Managing)Cybercx 2021 - 2023Auckland, New ZealandIn 2020, Insomnia Security was acquired by CyberCX. As a senior and experienced member of the team, I took on variety of practice-level responsibilities, including scoping and scheduling of complex engagements across the entire NZ practice, as well as end-to-end responsibility of NZ-based adversary simulation engagements (e.g. red, purple teams) with high profile clients. -
Principal Security ConsultantCybercx 2018 - 2021Auckland, New ZealandWhile continuing to deliver penetration testing and other security engagements, I developed technical specialisations in areas including cloud security, modern DevOps, wireless networking and password cracking, as well as specific expertise in domains such as payments, telecommunications, industrial control systems and aviation.I began leading a team of experienced consultants, with a focus on professional development, performance and advocacy. I also took on a central role around the lifecycle of engagements, undertaking detailed scoping work, delivery, as well as follow-up and presentation. -
Senior Security ConsultantCybercx 2015 - 2018Auckland, New ZealandAs my experience at Insomnia grew, I picked up further responsibilities and technical specialisations while continuing to deliver high-quality client engagements. These include deploying and managing infrastructure to support delivery including test labs, leading more complex client engagements (e.g. Red Teams), undertaking research and tool development and giving technical talks and presentations at local conferences and meetups, including Kiwicon, OWASP and ISIG. -
Security ConsultantCybercx May 2013 - 2015Auckland, New ZealandA technical consultant role at a boutique security practice, specialising in delivering offensive securitytesting engagements for clients. -
Security ConsultantInsomnia Security May 2013 - Oct 2020Auckland, New ZealandInsomnia Security was acquired by CyberCX in 2020
-
Full Stack DeveloperMighty Ape Jul 2008 - May 2013Auckland, New ZealandI joined Mighty Ape when the employee count was still in single digits. My role began as "Web Developer", taking care of changes to the previous site, templating marketing emails etc. with a small team.As Mighty Ape launched and grew, so did my role - encompassing full stack development of not only the website itself, but the software that powered the organisation - inventory, fulfilment, financial reporting, external integration etc.I also took on further responsibilities within the organisation, designing, deploying and maintaining the organisation's network and application infrastructure, databases, phone system as well as security responsibilities including intrusion detection and compliance (PCI DSS).My time at Mighty Ape showed me how effective small teams can be when they work closely with parts of the business, with an openness to adopt solutions that work, even if they eschew the current flavours-of-the-month. -
Support EngineerComverse 2006 - 2008Auckland, New ZealandTier 3 Support engineer and systems administrator supporting Vodafone NZ messaging systems. -
Junior Software DeveloperNothing But Net Nz Ltd 2005 - 2006Auckland, New Zealand
Chris Smith Education Details
-
Computer Science
Frequently Asked Questions about Chris Smith
What is Chris Smith's role at the current company?
Chris Smith's current role is Security engineering and disassembly.
What schools did Chris Smith attend?
Chris Smith attended Massey University.
Not the Chris Smith you were looking for?
-
2yahoo.co.uk, clarksons.com
-
1cmcmarkets.com
-
Chris Smith
Security Manager At Wellington Institute Of Technology And Whitireia Community Polytechnic.Wellington, New Zealand -
-
1xtra.co.nz
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial